Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.3) | 0.60% | — | Webassembly Binary Toolkit | 2/4/2025 | 17/6/2026 | A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the function BinaryReaderInterp::BeginFunctionBody of the file src/interp/binary-reader-interp.cc. The manipulation leads to null pointer dereference. The attack can be launched remotely. The complexity of… | |
| Aplazada | Alta (7.1) | 0.18% | — | Mendibass Browser Address BAR ColorAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mendibass Browser Address Bar Color browser-address-bar-color allows Stored XSS.This issue affects Browser Address Bar Color: from n/a through <= 3.3. | |
| Analizada | Baja (2.3) | 0.50% | — | Webassembly Wabt | 21/3/2025 | 17/6/2026 | A vulnerability was found in WebAssembly wabt 1.0.36. It has been declared as critical. This vulnerability affects the function BinaryReaderInterp::GetReturnCallDropKeepCount of the file wabt/src/interp/binary-reader-interp.cc. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely.… | |
| Analizada | Media (5.3) | 0.57% | — | Webassembly Wabt | 17/3/2025 | 17/6/2026 | A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport of the file wabt/src/interp/binary-reader-interp.cc of the component Malformed File Handler. The manipulation leads to heap-based buffer… | |
| Analizada | Alta (7.5) | 0.51% | — | Bytecodealliance Webassembly Micro Runtime | 8/11/2024 | 17/6/2026 | wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types. | |
| Analizada | Alta (7.8) | 0.63% | — | Bytecodealliance Webassembly Micro Runtime | 8/11/2024 | 17/6/2026 | An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the check_was_abi_compatibility function. | |
| Analizada | Alta (7.5) | 0.76% | — | Bytecodealliance Webassembly Micro Runtime | 6/5/2024 | 17/6/2026 | An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h. | |
| Analizada | Media (6.2) | 0.33% | — | Bytecodealliance Webassembly Micro Runtime | 6/5/2024 | 17/6/2026 | A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service via the "wasm_loader_check_br" function in core/iwasm/interpreter/wasm_loader.c. | |
| Modificada | Crítica (9.8) | 0.70% | — | Mitel Unify Openscape Xpressions Webassistant | 8/2/2024 | 17/6/2026 | An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal. | |
| Modificada | Alta (8.8) | 0.92% | — | Mitel Unify Openscape Xpressions Webassistant | 8/2/2024 | 17/6/2026 | An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload. | |
| Modificada | Media (5.5) | 0.32% | — | Bytecodealliance Webassembly Micro Runtime | 31/12/2023 | 17/6/2026 | Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled. | |
| Modificada | Alta (7.5) | 1.0% | — | Bytecodealliance Webassembly Micro Runtime | 22/11/2023 | 9/7/2026 | An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service via the wasm_loader_prepare_bytecode function in core/iwasm/interpreter/wasm_loader.c. | |
| Modificada | Media (5.5) | 0.21% | — | Webassembly Binary Toolkit | 23/10/2023 | 17/6/2026 | WebAssembly wabt 1.0.33 has an Out-of-Bound Memory Read in in DataSegment::IsValidRange(), which lead to segmentation fault. | |
| Modificada | Media (5.5) | 0.27% | — | Webassembly Binary Toolkit | 23/10/2023 | 17/6/2026 | WebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault. | |
| Modificada | Media (6.5) | 0.62% | — | Webassembly Binaryen | 22/8/2023 | 17/6/2026 | Heap-buffer-overflow in /src/wasm/wasm-binary.cpp in wasm::WasmBinaryBuilder::visitBlock(wasm::Block*) in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-opt. | |
| Modificada | Media (6.5) | 0.61% | — | Webassembly Binaryen | 22/8/2023 | 17/6/2026 | A NULL pointer dereference was discovered in SExpressionWasmBuilder::makeBlock in wasm/wasm-s-parser.c in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-as. | |
| Modificada | Media (5.5) | 0.28% | — | Webassembly Binary Toolkit | 23/5/2023 | 17/6/2026 | WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote ("). | |
| Modificada | Alta (7.5) | 0.83% | — | Webassembly Binary Toolkit | 23/5/2023 | 17/6/2026 | An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a Denial of Service (DoS) via running a crafted binary. | |
| Modificada | Media (5.5) | 0.28% | — | W3 Webassembly | 3/5/2023 | 17/6/2026 | An issue in the component hang.wasm of WebAssembly 1.0 causes an infinite loop. | |
| Modificada | Media (5.5) | 0.28% | — | Webassembly Wabt | 10/3/2023 | 17/6/2026 | WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild. | |
| Modificada | Alta (7.8) | 0.32% | — | Webassembly | 10/3/2023 | 17/6/2026 | WebAssembly v1.0.29 was discovered to contain a heap overflow via the component component wabt::Node::operator. | |
| Modificada | Media (5.5) | 0.29% | — | Webassembly | 10/3/2023 | 17/6/2026 | WebAssembly v1.0.29 discovered to contain an abort in CWriter::MangleType. | |
| Modificada | Media (5.5) | 0.31% | — | Webassembly | 10/3/2023 | 17/6/2026 | WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::cat_compute_size. | |
| Modificada | Media (5.5) | 0.27% | — | Webassembly Wabt | 28/10/2022 | 17/6/2026 | wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write. | |
| Modificada | Alta (7.1) | 0.31% | — | Webassembly Wabt | 28/10/2022 | 17/6/2026 | wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount. |